What Is Crypto Ransomware? How Encryption Attacks Work
Crypto ransomware encrypts files and demands payment for the key. See how hybrid encryption works, how attacks unfold, recovery odds, and detection signals.
Crypto ransomware is malware that encrypts a victim's files and demands payment for the decryption key. The operating system keeps running, applications stay open, but the data inside them becomes unreadable ciphertext.
In this context, crypto refers to cryptography, not cryptocurrency, despite the overlap in practice. Attackers collect in cryptocurrency for its own reasons, covered further down, and the name refers to the encryption that locks the files.
One point shapes everything that follows: in enterprise attacks, encryption is the last step, not the first. By the time files start changing, the operators have spent days inside the network stealing credentials, mapping shares, and deleting backups.
How Crypto Ransomware Encryption Works
Modern crypto ransomware uses hybrid encryption: a fast symmetric cipher for the files, and asymmetric cryptography to lock the key that decrypts them.
That sequence stays consistent across families. The ransomware generates a random symmetric key, AES-256 or ChaCha20 in most families, and encrypts each file with it. That symmetric key is then encrypted with the attacker's RSA or elliptic-curve public key and written into the encrypted file or a key blob. Only the matching private key, held on the attacker's infrastructure, unwraps it.
Defenders lose the obvious escape route with that design. Brute-forcing AES-256 is not a realistic option for anyone, and the private key never touches the victim's environment, so "just crack the encryption" never appears in a serious recovery plan.
Older families were recoverable for reasons that had nothing to do with cipher strength. Weak random number generation, reused keys across victims, keys left in memory, and keys recovered during law enforcement seizures all produced free decryptors. Those mistakes have grown rare.
Speed changed the math for defenders more recently. Intermittent encryption, where the ransomware encrypts alternating chunks of each file instead of the whole thing, renders data unusable while cutting encryption time sharply, which shortens the window in which a defender can interrupt the process.
How a Crypto Ransomware Attack Works
A crypto ransomware attack runs through six stages, and only the last one is visible to the victim.
Initial access: Stolen VPN or RDP credentials, an exploited internet-facing appliance, a phishing attachment, or access purchased from a broker who already holds a foothold.
Escalation and discovery: Credential theft with tools such as Mimikatz, privilege escalation to domain administrator, and enumeration of file shares, hypervisors, and backup servers.
Exfiltration: Copying sensitive data out, in most cases to cloud storage, so the crew can extort even when the victim restores cleanly.
Backup destruction: Deleting shadow copies, stopping backup agents, corrupting local repositories, and hunting for the backup console itself.
Encryption: Deployment across the estate through group policy or a remote management tool, timed for a weekend or a holiday.
Extortion: A ransom note, a countdown, a leak site listing, and in many cases calls or emails to customers and regulators.
Affiliate economics split this work further. In the ransomware-as-a-service model, an affiliate handles the intrusion, the core group supplies the encryptor and the negotiation portal, and the two divide the payment, so tactics vary widely between incidents attributed to the same family.
What Crypto Ransomware Targets First
Operators pick targets by how fast the loss stops the business, not by file count.
Databases and file shares: Production data that applications read from, where encryption halts operations within minutes.
Virtualization hosts: ESXi and Hyper-V servers, where encrypting datastores takes out dozens of virtual machines at once.
Backup repositories: Backup servers, NAS devices, and anything mounted with write access, attacked before the main encryption run.
Document stores: Finance records, contracts, engineering files, and email archives that carry regulatory weight.
Synchronized cloud folders: OneDrive, Google Drive, and Dropbox clients that faithfully replicate the encrypted versions upward.
Operating system files stay untouched by design. A machine that fails to boot cannot display a ransom note or process a payment.
Crypto Ransomware vs Locker Ransomware vs Extortion-Only Attacks
These three models sit under the ransomware label, and they differ in what gets taken and what recovery costs.
Aspect
Crypto ransomware
Locker ransomware
Extortion-only
What it does
Encrypts files and demands a key fee
Locks the screen or device
Steals data, no encryption
System usability
System runs, data unreadable
Device unusable
Nothing visibly changes
Recovery path
Backups, or the attacker's decryptor
Reimage or reset
No technical recovery
Main pressure
Downtime plus data loss
Loss of device access
Publication and regulatory exposure
Typical targets
Enterprises and data-heavy operations
Consumers and shared devices
Organizations holding sensitive data
Backups help
Yes, when offline and tested
Rarely needed
No, the data is already copied
Watch that third column, because the market has moved toward it. Several crews now skip encryption entirely, since stealing data avoids the engineering effort of a reliable encryptor and still produces a payable threat, a pattern tracked across ransomware intelligence reporting.
Why Crypto Ransomware Demands Cryptocurrency
Cryptocurrency suits extortion because it settles across borders in minutes, resists reversal, and needs no bank to approve it. Bitcoin dominates for liquidity, and some crews price in Monero or charge a premium for Bitcoin because of its traceability.
Traceability cuts both ways, and the numbers show it. Chainalysis tracked roughly $820 million in on-chain ransomware payments during 2025, an 8% decline, with the share of victims paying falling to about 28% even as claimed attacks rose 50%.
Read those two figures together, and the business model looks strained rather than healthy. More victims are refusing, regulatory pressure on payments has increased, and blockchain analytics firms trace wallets well enough that cashing out has become the operators' hardest problem.
Can Files Encrypted by Crypto Ransomware Be Recovered?
Recovery depends almost entirely on decisions made before the attack. Four paths exist, and only one is reliable.
Offline backups: The dependable route, provided the backups were isolated, recent, and restore-tested.Â
Free decryptors: The No More Ransom project publishes tools for families where keys leaked, or the crypto was flawed. Current families rarely qualify.
Paying for the attacker's decryptor: A partial fix at best. Decryptors run slowly, corrupt large files, and never undo the theft that preceded encryption.
Forensic recovery: Shadow copies, unencrypted temporary files, and keys recovered from memory occasionally help on single machines. Enterprise-wide, this rarely scales.
Rebuilding beats decrypting in most incidents, even when the key arrives. A decryptor restores files to systems that an attacker controlled for days, which means the environment still needs rebuilding, credentials still need rotating, and the persistence mechanisms still need hunting.
Detecting Crypto Ransomware Before Encryption Starts
Detection that fires once files start changing arrives far past the point of saving much. The signals worth alerting on appear in the hours and days before encryption.
Backup tampering: vssadmin or wmic deleting shadow copies, bcdedit disabling recovery, backup services stopped, or a backup console login from an unusual account.
Security tooling interference: EDR agents uninstalled, tamper protection disabled, or Defender exclusions added estate-wide through group policy.
Credential and movement patterns: LSASS access, new domain administrator accounts, and RDP sessions between hosts that never communicate, ideally caught by security monitoring rules.
Staging and exfiltration: Large archives appearing in temporary directories, and outbound transfers to cloud storage services the business does not use.
Canary files: Monitored decoy files in file shares that trigger an alert the instant anything modifies them.
Mass file behavior: Sudden spikes in file renames, extension changes, and entropy across a share, the last reliable signal before widespread damage.
Hypervisors need separate attention from the rest of the estate. ESXi hosts produce limited telemetry, rarely run agents, and an SSH login followed by a mass VM shutdown deserves an immediate response from the SOC.
How to Protect Yourself from Crypto Ransomware Attack
Enforce phishing-resistant MFA on VPN, RDP gateways, email, and administrative access, since stolen credentials open most intrusions.
Patch internet-facing systems first, prioritizing the edge appliances that ransomware affiliates exploit within days of disclosure.
Keep immutable, offline backups of critical systems, and test restores on a schedule instead of trusting the backup job status.
Segment the network so a compromised workstation cannot reach hypervisors, backup servers, or domain controllers directly.
Tier administrative accounts and randomize local administrator passwords, which breaks the credential reuse that speeds lateral movement.
Enable EDR tamper protection and alert when agents stop reporting, since attackers disable tooling before deploying the encryptor.
Harden and monitor hypervisors, restricting SSH and console access to a jump host with logging.
Monitor for exposed credentials through leaked credential monitoring and dark web monitoring, where access to the organization appears for sale first.
Review supplier access, because a third-party breach gives affiliates a route that bypasses the perimeter entirely.
What to Do After a Crypto Ransomware Attack
Isolate affected systems from the network while keeping them powered on, since memory holds evidence and occasionally keys.
Preserve evidence before rebuilding: ransom notes, encrypted samples, logs, and the timeline of first access.
Determine what left the network, since exfiltration decides the notification and regulatory picture more than encryption does.
Verify backup integrity on an isolated system before restoring anything into a network that nobody has cleared yet.
Engage legal counsel, insurers, and incident response early, and report to authorities such as the FBI's IC3 or CERT-In.
Check sanctions exposure before any payment discussion, because paying certain groups carries legal liability of its own.
Rotate every credential and key, including domain key material, service accounts, and API tokens within the attacker's reach.
Hunt before reconnecting, since operators routinely return through persistence nobody found during the first cleanup.
Crypto Ransomware Examples
Families change names constantly, and the mechanics stay recognizable across generations.
CryptoLocker (2013): The family that proved the model, pairing RSA-2048 key wrapping with Bitcoin payments before a takedown recovered its key database.
WannaCry (2017): A worm that spread through an SMB vulnerability and encrypted systems across hospitals and manufacturers within hours.
LockBit: A long-running affiliate operation whose builder leaked publicly, seeding derivative encryptors still in use today.
Qilin: A current RaaS operation with cross-platform encryptors that target Windows and ESXi environments, covered in CloudSEK's Qilin analysis.
SafePay: A closed group built on leaked LockBit code, entering through stolen VPN credentials instead of affiliates, profiled in CloudSEK's SafePay breakdown.
Cl0p: An operation that increasingly skips encryption, exploiting file transfer software to steal data and extort at scale.
Spotting Crypto Ransomware Precursors With CloudSEK XVigil
Every enterprise ransomware case starts with something an attacker obtained before the intrusion: a working credential, an exposed service, or access bought from a broker who found both.
CloudSEK XVigil monitors deep, dark, and surface web sources for those precursors, including leaked employee credentials, infostealer logs tied to corporate accounts, access listings describing the organization, and leak-site posts naming it or its suppliers.
None of that stops an encryptor that is already running. It buys the window that matters instead, since a credential reset the week before a planned intrusion costs far less than a restore.
Crypto Ransomware FAQs
Can antivirus stop crypto ransomware?
Partly. Signature tools catch known binaries, while current families need behavioral detection on backup deletion, mass file changes, and security tool tampering.
Does crypto ransomware affect cloud storage?
Yes. Sync clients replicate encrypted files upward, though version history and retention policies allow recovery of earlier copies.
Can crypto ransomware encrypt external drives?
Yes. Any drive mounted with write access is a target, so backup media stays disconnected between backup runs.
How do security teams identify the ransomware family?
Analysts match the ransom note, file extension, and encryption artifacts against services such as ID Ransomware and the No More Ransom database.
Cyber attack vectors include phishing, compromised credentials, exposed software, API abuse, supply chain threats, and other paths attackers use for initial access.
Pastebin is a free site for sharing plain text and code via a link. How Pastebin works, its legitimate uses, security risks, and how attackers abuse it.
Personally identifiable information (PII) is any data that identifies a specific person. PII types, examples, exposure risks, and the laws that govern it.